S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Apr 9, 2026

CVE-2026-29066 Scanner

CVE-2026-29066 Scanner - Path Traversal vulnerability in TinaCMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-29066
6.2
CVSSmedium
Requires local system access · no authentication required.

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This vulnerability is fixed in 2.1.8.

Attack Vector
Local
Privileges Req.
None
User Interaction
None
Affected
cliby @tinacms
< 2.1.8
Updated Aug 21, 2026View on NVD →
Detail

TinaCMS is an open-source content management system that offers a flexible content editing solution for websites, commonly used by developers for site editing and content management tasks. It is designed to be utilized in modern web applications, making it a favorite in environments requiring dynamic content management. Developers and designers use TinaCMS to integrate with various frontend frameworks, benefiting from its real-time editing capabilities. The product's CLI is used to manage development servers, providing a seamless environment for content and site development. With its growing community, TinaCMS continuously evolves, offering a robust solution for web content management. As such, keeping it secure is vital, and understanding potential vulnerabilities is crucial for users.

Path Traversal vulnerabilities in TinaCMS occur due to improper handling of server paths, allowing unauthorized access to sensitive files. This specific vulnerability is found in the product version before 2.1.8 due to a misconfigured Vite server.fs.strict setting. Attackers exploiting this flaw can potentially access critical files stored on the host system. The vulnerability is rated medium severity due to its exploitability via the development server. Systems with this configuration exposed may inadvertently provide attackers access to a wealth of information, leading to data breaches. Understanding the nature of the Path Traversal flaw is critical for developers and administrators maintaining these systems.

The technical details of this vulnerability involve improper restrictions within the TinaCMS CLI. Attackers use HTTP requests to traverse directories and access files, utilizing paths like '/etc/passwd' to reveal sensitive system information. The vulnerability arises due to a lack of stringent checks on server file system settings, which can be exploited remotely by unauthenticated users. Ensuring server configurations, such as Vite server settings, are correctly applied is essential to mitigate this risk. The endpoint visible in HTTP requests often allows for unauthorized access, making it imperative for users to update and secure installations swiftly. This Path Traversal flaw highlights the importance of strict configuration management.

If exploited, this vulnerability could lead to unauthorized file access and potential data exfiltration. Sensitive files, such as credential files, can be targeted, leading to security disclosures and data loss. In extreme cases, this may escalate to further system compromise if attackers locate and utilize sensitive information. Network integrity could be compromised, affecting overall organizational security posture. Users must act quickly to patch this flaw to prevent possible exploitation. Such vulnerabilities underline the necessity for continuous monitoring and updating of software components to maintain security resilience.

REFERENCES

Solution Advice
  • Update TinaCMS to version 2.1.8 or later to patch the vulnerability.
  • Enable strict server configuration settings to prevent path traversal.
  • Regularly review and audit server settings to ensure they align with security best practices.
  • Implement access controls to limit exposure of sensitive files.
  • Consider using a web application firewall (WAF) to filter malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.